Vulnerabilidades en PHOENIX CONTACT

190 resultados
Análisis Vexday

Com 73 CVEs catalogadas, os produtos PHOENIX CONTACT apresentam taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, 9 vulnerabilidades de severidade crítica merecem atenção prioritária, especialmente considerando que o tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria historicamente associada a impactos severos em ambientes industriais e de automação. A CVE mais perigosa atualmente identificada é CVE-2023-3526, com escore EPSS de 0,0158, indicando probabilidade de exploração baixa porém não desprezível. A presença de PoC pública para ao menos uma vulnerabilidade reforça a necessidade de monitoramento contínuo, mesmo na ausência de exploração ativa confirmada.

CVE-2024-28134HIGHPHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series EPSS 0.5%CVE-2025-41694MEDIUMAuthenticated Denial-of-Service via WebshellEPSS 0.5%CVE-2024-7734MEDIUMPhoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.EPSS 0.5%CVE-2026-7849CRITICALCommand Injection in SCM (idledisconnect parameter)EPSS 0.5%CVE-2025-41705MEDIUMPhoenix Contact: WebSocket Message Interception Leaks Webfrontend CredentialsEPSS 0.5%CVE-2018-25112HIGHPHOENIX CONTACT: ILC 1x1 ETH Denial of ServiceEPSS 0.5%CVE-2020-12521MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: A specially crafted LLDP packet may lead to a high system load in the PROFINET stack.EPSS 0.5%CVE-2023-37858MEDIUMPHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsEPSS 0.5%CVE-2026-44101CRITICALOCPP reconfiguration vulnerabilityEPSS 0.4%CVE-2026-44090CRITICALMissing authentication for MQTT BrokerEPSS 0.4%CVE-2023-37864HIGHPHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity checkEPSS 0.4%CVE-2026-44092HIGHMissing input validation / stripping of CRLF characters in SystemConfigManagerEPSS 0.4%CVE-2025-41770HIGHUnauthenticated Denial of ServiceEPSS 0.4%CVE-2024-25999HIGHPHOENIX CONTACT: Privilege escalation in the OCPP agent serviceEPSS 0.4%CVE-2024-7698MEDIUMPhoenix Contact: Access to CSRF tokens of higher privileged users in MGUARD productsEPSS 0.4%CVE-2020-12499HIGHPHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier: Improper path sanitation vulnerability.EPSS 0.4%CVE-2024-25996MEDIUMPHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series EPSS 0.4%CVE-2024-11497HIGHPhoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalationEPSS 0.4%CVE-2024-28133HIGHPHOENIX CONTACT: Privilege escalation in CHARX Series EPSS 0.4%CVE-2026-22316MEDIUMBuffer Overflow using TFTP FilenameEPSS 0.4%